Cong Pu

dblp:189/9268 · DBLP profile ↗
← Back
33ranked-venue papers
22as first author
21since 2021 · last 2026
0000-0002-7952-0038ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 8 first-author · 6 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Privacy Preserving Federated Learning-Based Authentication Scheme for Internet of Drones Systems
abstract
As the drone technology rapidly progresses, the notion of Internet of Drones (IoD) has surfaced as a vital framework for facilitating connections between aerial drones and existing cyber infrastructures. With ubiquitous IoD applications deployed in the modern cities, we need to focus on resolving security and privacy matters before enjoying the welfare benefits brought by these advanced applications. A minority of machine learning-based authentication systems recently emerged in the Internet of Things (IoT) community, however, these intelligent techniques have the data privacy and scalability problems. To confront the current unresolved authentication challenges in the realm of IoD, we propose a novel federated learning (FL) based authentication scheme, also referred to as FLASH, for futuristic IoD systems. The FLASH’s basic idea is that a deep neural network (DNN) architecture is deployed with the ground stations to train an authentication model with drones’ radio characteristics (e.g., carrier frequency offset and I-Q imbalance) in a decentralized way. The newly trained local models at the ground stations are encrypted using homomorphic encryption and send back to the IoD federated server for the aggregation of a new global authentication model. We conduct an experimental study in MATLAB and evaluate the performance of FLASH and other four benchmark schemes; the simulation results demonstrate that the FLASH is more effective than its counterparts.
Image Bhattarai, Cong Pu
CCNC2
2026 Deep Reinforcement Learning-Based Data Download Scheduling Algorithm for Internet of Drones Systems
abstract
The Internet of Drones (IoD) paradigm has noticed a growing demand for efficient and sustainable operations management, with a particular emphasis on service request scheduling. As IoD systems become widespread in various domains, such as ecological surveillance, facilities evaluation, etc., it is crucial to efficiently manage and prioritize the execution of drones’ data download requests at the ground stations. Due to the unique characteristics of IoD systems, e.g., high drone density and mobility, limited ground station communication range and energy resources, and substantial deployment and maintenance cost, how to enable the ground stations to scalably, intelligently, and optimally answer drones’ data download requests concurrently has become a challenging issue. In this paper, we propose a deep reinforcement learning-based data download request scheduling mechanism (hereafter referred to as DrDre), enabling ground stations to plan and execute received data download requests from drones in a scalable, intelligent, and optimal manner. DrDre takes into account various scheduling parameters such as request deadline, request urgency, request priority, requested data size, and data popularity when making scheduling decisions. In addition, DrDre exploits the deep reinforcement learning and deep Q-learning frameworks to formulate the dynamic IoD environment into a Markov Decision Process (MDP) model and enable ground stations to learn an optimal scheduling policy in order to maximize cumulative rewards over time, respectively. We conduct extensive and comparative simulation-based experiments in a customized simulation environment using SUMO and Python. Simulation results show that DrDre outperforms the selected benchmark schemes in terms of request satisfaction rate, request fulfillment latency, the amount of downloaded data, and the number of incomplete requests.
Image Bhattarai, Cong Pu
CCNC2
2026 Quantum-Safe and Cross-Layer Authentication and Key Agreement Protocol for Smart Grid Communications
abstract
The extensive value and importance of smart grids are evident in their transformative impact on sustainable urban development. However, the swift progression of quantum computing has made the security and privacy of smart grid communications a pressing and vital issue. Although considerable studies have been carried out on authentication and key agreement within smart grids, the predominant body of solutions either come with substantial computation, communication, and storage overheads, or are primarily single-layer schemes. More importantly, they are not designed to withstand advanced quantum attacks. In this paper, we propose a novel quantum-safe and cross-layer authentication and key agreement protocol, named QCLaka, for smart grid communications that overcomes the shortcomings of existing approaches and offers advanced security and functionality features. The proposed QCLakaprotocol integrates lattice-based cryptography with probability physical unclonable function (Prob-PUF) to enable the local gateway and the smart meter to mutually authenticate each other and establish a secure session key. The security of the proposed QCLakaprotocol is assessed through formal security verification to highlight its safety in adversarial environments and its ability to withstand both well-known and advanced cyberattacks. Additionally, the experimental evaluation shows that the proposed QCLakaprotocol outperforms the benchmark schemes regarding the performance in security and efficiency.
Cong Pu, Muhammad Abdullah Bilal, Sunho Lim
CCNC1
2026 Authenticated Key Agreement Protocol for Device-to-Gateway Communication in IoT
abstract
The advent of Internet of Things (IoT) ushers in a significant potential to integrate individuals, devices, and data, leading to a profound change in our professional and social environments. The small, resource-constrained IoT devices are usually deployed to collect various types of critical data in remote or unmonitored locations. Due to extensive interconnectivity, limited resources, and inadequate security design, IoT systems are vulnerable to communication-specific cyber threats, which aim to disrupt operations, steal sensitive information, or cause damage. To resolve the security concerns in IoT communications, many recent efforts have been devoted to designing authenticated key agreement protocols for IoT systems. However, not only most of the existing solutions fail to adopt cost-effective techniques for resource-limited IoT devices, but also they ignore the differentiation among various data types in the established session keys. A few approaches use traditional physical unclonable functions (PUFs) to address resource concerns, yet they introduce new security issues into IoT systems. Once the PUF cryptographic information is compromised by machine learning attacks, the entire authentication framework collapses. Therefore, in this paper we propose an authenticated key agreement protocol for device-to-gateway communication in IoT systems based on Chebyshev polynomial and probability-based PUF. We examine the proposed protocol’s security features through formal security validation. We also conduct performance evaluation through a simulation-oriented study, and the results clearly prove that the proposed protocol offers superior security and privacy, while maintaining low computational overhead.
Cong Pu, Jongho Seol, Nohpill Park, Dragan Korac
CCNC1
2025 Secure and Privacy-Preserving Data Aggregation Against Malicious Gateway in RPL-Based Internet of Things
abstract
In the era of Industry 4.0 (4IR), the Internet of Things (IoT) drives the transformation of conventional operation mode into intelligent systems through interconnecting smart devices to monitor, analyze, and optimize the target applications. In order to achieve energy-saving data transmission, a routing protocol, called RPL, has been specified for resource-challenged IoT devices and networks. In the context of 4IR, the IoT technology is being widely used for mission-critical systems, and the data collected by IoT devices might contain privacy-sensitive information. In addition, the IoT gateway could be compromised due to the lack of necessary and persistent physical and/or logical security protection. Hence, the protection of data security and privacy becomes a crucial factor for RPL-based IoT systems to realize their quality of service requirements and objectives successfully. In this paper, we propose a secure and privacy-preserving data aggregation approach, called SPARDA, for IoT devices and networks running the RPL routing protocol. SPARDA is realized with physical unclonable function, homomorphic encryption, and trapdoor function, and is perfectly integrated with the RPL routing protocol to prevent the malicious IoT gateway from either accessing, falsificating, or corrupting the real-time data from IoT devices throughout the data gathering and summarization phase. We choose an automatic security protocol verification tool, widely known as AVISPA, to analyze and verify the security specification of SPARDA. We also conduct an experimental study to evaluate the performance of SPARDA by comparing with benchmark methods. The experimental results indicate that not only does SPARDA protect IoT networks from malicious gateway attacks, but it also outperforms existing schemes in terms of computation and storage overheads while satisfying all critical security and privacy criteria.
Image Bhattarai, Cong Pu
IPCCC2
2025 Quantitative Study on the Performance of an Asynchronous Chain Model
abstract
This article presents a quantitative study on the performance of an asynchronous chain model [ 31 ] during its theoretical design stage. The asynchronous chain [ 31 ] in this study is asynchronous along with adaptively sized blocks in a proactive manner, whereas the conventional chain controls the block posting in a strictly synchronous manner to the fixed-sized blocks. The model of the adaptive chain, with a rather “reactively” dynamic size of blocks as shown in [ 30 ], can be compared with the proposed model, which is asynchronous with a “proactively” dynamic size of the blocks. It is assumed in this article that Variable Bulk Arrivals (VBA) of transactions in the Poisson distribution and Asynchronous Bulk Posting (ABS) of transactions off a block potentially in different capacity in exponential time, referred to as VBAABS. Basic numerical simulations results have been reported in [ 31 ] primarily for feasibility validation purpose. In our earlier conference version [ 31 ], we have presented the work with the focus on development and validation of the performance model in a quantitative manner with extensive numerical simulations to demonstrate the efficacy of the proposed asynchronous chain model, and in this article, we extend the work to also include substantially new works such as an extensive comparative study in performance versus other blockchain models such as the baseline chain model [ 29 ] (see Comparison between the Asynchronous Chain Model and the Baseline Chain Model) and the adaptive chain model [ 30 ] (see Comparison between the Asynchronous Chain Model and the Adaptive Chain Model under Various Network Traffic). Then, a summary, by each chain model in consideration, is provided for clarity (see Chain Model Insights). Furthermore, a new simulation is conducted with a focus on the performance of microtransactions as a type of transactions to be commonly expected in the gaming decentralized applications to demonstrate the benefit from the proactive asynchrony of block postings (see Simulation and Analysis of the Impact of the Asynchronous Chain Model on the Performance of Microtransactions). Last, the implementation results and analysis are shown based on the Ethereum open source as reported in [ 31 ].
Jongho Seol, Cong Pu, Nohpill Park
Distributed Ledger Technol. Res. Pract.2
2025 A Redactable Blockchain-Assisted Application-Aware Authentication System for Internet of Drones
abstract
The Internet of Drones (IoD) has latterly started to gear up its applications in diverse sectors of the society as a result of high adaptability and adjustability to new circumstances. Security, privacy, and storage issues still remain as major barriers for next-generation IoD systems to meet their general applicability requirements, even though many one-keyfor-all static authentication and append-only blockchain assisted systems have been proposed by the IoD community. First, bearing channel bandwidth and drones resource constraints in mind, authentication protocols with less computation and communication overhead are preferable. Second, the IoD drones might collect different types of data simultaneously, a unique secret session key for each type of data is needed to prevent data leakage from unauthorized parties. Third, the permanent storage of each drones cryptographic and task information on the appendonly blockchain raises significantly alert after a long period of operation and/or an exponential growth of drones. Motivated by the research challenges presented above, we propose a redactable blockchain-assisted application-aware authentication system, also referred to as ReBAS, for next-generation IoD applications, where the drones shuttle back and forth between different flying zones to collect diverse types of data. The Chebyshev polynomial, redactable consortium blockchain, and chameleon hash function are adopted to significantly minimize the computational, communication, and storage overheads of cryptography-related operations. According to the security verification, and formal and informal security analysis, the ReBAS not only guarantees secure and dynamic authenticated key establishment, but also is in compliance with the security requirements of Canetti-Krawczyk adversarial framework. We also develop a rigorous simulation framework and conduct an extensive comparative study. The experimental results demonstrate that the ReBAS can minimize the overheads in computation, communication, and storage while enhancing scalability.
Cong Pu, Muhammad Abdullah Bilal, Nohpill Park, Jongho Seol, Kim-Kwang Raymond Choo
IEEE Internet Things J.1
2025 Management of evaluation processes and creation of authentication metrics: Artificial intelligence-based fusion framework
abstract
While the literature extensively covers various authentication systems, management of evaluation processes and creation of authentication metrics remain significant information challenges for researchers. To overcome this complex challenge, we present a taxonomy of research processes based on fusion and fuzzy strategies and give an overview and comparison of related studies. Specifically, we develop an artificial intelligence-based fusion framework ( f f ) incorporating Mamdani-type fuzzy rules and key user factors: security, privacy, and trust. Its uniqueness and innovation lie in the application of trapezoidal functions to describe these factors as key input metric values. Moreover, we are the first to incorporate trust as an independent comparative factor and provide a comparison of traditional and modern authentication methods, including artificial intelligence (AI), electroencephalogram (EEG), electrocardiographic (ECG), and photoplethysmogram (PPG) methods. Also, we use a workflow diagram to define the topological relationships among user factors and authentication factors, clarifying the role of fusion in multi-factor authentication (MFA) approaches. In comparison to other similar frameworks implemented solely for traditional methods, the proposed f f yields better and more realistic quantification metric results. In addition, we present and discuss the key mathematical differences between one-factor authentication (1FA) and MFA, aiming to shed light on issues such as complexity and bias. Lastly, the developed f f not only advances MFA metrics by introducing modern authentication methods such as AI, EEG, ECG, and PPG but also paves the way for future research on how and why AI algorithms need to be incorporated into information processing and the creation of strong MFA solutions.
Dragan Korac, Boris Damjanovic, Dejan Simic, Cong Pu
Inf. Process. Manag.4
2025 FastPlan: A three-step framework for accelerating drone-centric search operations in post-disaster relief
Sunho Lim, Ingyu Lee, Gyu Sang Choi, Jinseok Chae, Ellora Ashish, Eric Ward, Cong Pu
Pervasive Mob. Comput.7
2024 A Lightweight Aggregate Authentication Protocol for Internet of Drones
abstract
The Internet of Drones (IoD), an innovative aerial-ground communication architecture, has quickly became the driving force for various civilian applications (e.g., body temperature detecting drones during the global pandemic of coronavirus disease). In the IoD, a fleet of drones are deployed over an area of interest, collect task-specific data, and then deliver them to the ground station for further data exploration and analysis. To fully exploit the potential of IoD in today's dynamic and evolving cyber-threat environment, the security and efficiency challenges existing in the IoD communications should be well addressed. Some researchers have developed security mechanisms to enable the authentication between the ground station and the drones in the IoD systems. Nonetheless, those schemes mainly focus on the security aspect but overlook the importance of communication efficiency to the resource-constrained drones. In order to fill this research gap, this paper proposes a lightweight aggregate authentication scheme (hereafter referred to as liteAGAP) to tackle the challenges of communication security and efficiency together. Specifically, liteAGAP utilizes cryptographic primitives such as physical unclonable function and bilinear pairing to efficiently secure the data exchange between the ground station and a group of drones in the IoD systems. To evaluate its security performance, liteAGAP is first implemented in the security-sensitive protocol modeling language. Then, we analyze and verify liteAGAP using AVISPA, which is a well-known Internet security protocol verification framework. We also implement liteAGAP and its counterpart schemes in a simulation environment, where the simulation-based experiments are conducted to obtain the results of communication overhead, running time, memory storage usage, and energy consumption. According to the results of security verification/analysis and performance evaluation, we conclude that not only liteAGAP meets the expected security requirements, but also provides superior performance compared to the existing schemes.
Image Bhattarai, Cong Pu, Kim-Kwang Raymond Choo
CCNC2
2024 Chebyshev Polynomial and Private Blockchain Based Cross-Domain Authentication Protocol for IoD Networks
abstract
With the maturity of Internet of Things (IoT), one of its descendants, Internet of Drones (IoD) has reached far beyond its proposers' vision in the recent decade. The IoD paradigm inherits the advantages of its predecessor, however, it also has its own unique challenges due to the drone's limited resources as well as the large scale deployment of services. As drones might be deployed for critical missions that span over a wide geographical area, the security and feasibility concerns are raised when drones are communicating with the ground stations located in different domains. Lately, blockchain has quickly become the preferred technique to realize the cross-domain communications in the IoD environment. Nonetheless, the current schemes either implement authentication and key agreement with resource-hungry operations, do not provide all required/vital security guarantees, or have inherent security flaws. To tackle the abovementioned issues, we propose a Chebyshev polynomial and private blockchain based authentication protocol (hereafter referred to as polyBlock) for cross-domain communications in the IoD environment. In the polyBlock, the Chebyshev polynomial technique is adopted to validate the identity of drone and negotiate the session key with the ground station, while the private blockchain is utilized to store the drone's cryptographic information. Through carrying out the security validation on polyBlock using the automated tool AVISPA, we claim that the polyBlock is completely free of security design flaws and is capable to operate safely in the adversarial settings. In addition, we implement the polyBlock and two benchmark schemes in the Eclipse-based simulation environment, and measure their performance in terms of execution time and communication overhead. Based on experimental results, we conclude that the polyBlock can provide more superior performance than its counterparts.
Cong Pu, Kim-Kwang Raymond Choo, Image Bhattarai
CCNC1
2024 Integrating Generative AI with Data Structures and Algorithm Analysis Course Homework
abstract
This innovative practice full paper describes how to integrate generative Artificial Intelligence (AI) with Data Structures and Algorithm Analysis (CS2) homework at Oklahoma State University. Data Structures and Algorithm Analysis (CS2) course covers extremely important knowledge and skills of becoming a computer scientist. However, students might fail to meet the learning outcomes of CS2 course, somewhat due to the abstract nature of concepts but also because of a misunderstanding of concepts, the selection of inappropriate data structure and algorithm, a lack of effective debugging skills, and writing inefficient code. Currently we are in an Artificial Intelligence (AI) revolution, and generative AI (also widely known as AI chatbots) are already popular across college and university campuses. Generative AI that are designed to learn and mimic human conversation is capable of generating, translating, or paraphrasing text and answering questions in a way that is often indistinguishable from human-generated content. We investigate the above-mentioned potential challenges faced by students while learning CS2 course at Oklahoma State University (OSU) and redesign the course homework in Fall 2023 semester. The objectives of the redesigned course homework are to provide students with opportunities to use generative AI to support their learning in the CS2 course as well as measure the effectiveness of utilizing generative AI to improve student learning outcomes in the CS2 course. At the end of Fall 2023 semester, we conducted a student perception survey in the CS2 course and collected valuable feedback from 47 out of 61 students (77% response rate). In summary, 85.1%, 76.6%, 74.5%, 63.8%, and 70.2% respondents indicated that generative AI help to understand testing and debugging better, improve coding skills and code quality, design and implement efficient data structures and algorithms, select appropriate algorithms and data structures with the assistance of generative AI, and under-stand the importance of designing and implementing efficient data structures and algorithms, respectively. In this paper, we summarize the experience of redesigning CS2 course homework at OSU, share lessons learned, and provide candid suggestions for utilizing course homework in CS2 courses at other institutions.
Cong Pu
FIE1
2024 A Lightweight and Anonymous Application-Aware Authentication and Key Agreement Protocol for the Internet of Drones
abstract
The drone technology has continuously been evolving since the beginning of the first decade of the 21st century with exceptional growth over the last several years. To pave the way for an interoperable aerial-ground communication platform, the Internet of Drones (IoD) framework has emerged to systematically organize a batch of drones to collect multiple application-specific data simultaneously and report them to a close ground station. As the collected data might contain sensitive information, people become more critically aware of data security and privacy issues associated with IoD applications. Authentication and key agreement protocols are able to protect IoD data from unauthorized access. However, the recent schemes fail to distinguish between types of data during the authentication and key establishment process, which leads to data leakage that sensitive data are being accessed by unauthorized entities. To address the data leakage issue and fill the research gap, this paper proposes a lightweight and anonymous application-aware authentication and key agreement protocol (also called liteA4) for IoD systems. The fundamental idea of liteA4 is that the ground station and the drone perform data type-aware mutual authentication and establish separate session keys for different types of data before the drone delivers the collected data to the ground station. The major techniques such as hash function, bitwise XOR, and physical unclonable function (PUF) are used to implement liteA4. We select the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool to verify the security of liteA4 in the cyber-threat environment. We also set up a simulation framework and conduct comprehensive and comparative experiments to validate the performance of liteA4. Extensive experimental results demonstrate that liteA4 not only is a safe and reliable protocol in the adversarial setting, but also provides better results than its counterpart approaches in terms of communication overhead, computational time, storage cost, as well as energy consumption.
Image Bhattarai, Cong Pu, Kim-Kwang Raymond Choo, Dragan Korac
IEEE Internet Things J.2
2023 A Featherweight Authentication and Key Agreement Scheme for Internet of Drones Applications
abstract
The Internet of Drones (IoD) will have revolutionized civil and commercial applications, in much the similar way that the Internet of Things (IoT) transformed the way information is exchanged with other devices and systems over the Internet. The drones are generally considered to have constrained resources, which make them less compatible with complicated algorithms and more prone to attacks. Moreover, the IoD applications are facing information security and privacy challenges in the cyber-threat environment, where the adversary could intercept communicating messages and compromise their confidentiality or integrity. Consequently, the security protocols which are designed for IoD applications should not only provide desirable security guarantees, but also be resource-efficient. Existing authenticated key exchange protocols can authenticate the identities of communication parties and realize the exchange of session key, however, they either incur high communication overhead, suffer from non-negligible computational cost, or have inherent security design flaws. Thus, these approaches are not suitable for resource-constrained drones involved in critical IoD applications. To address the above challenges, this paper presents a featherweight authentication and key agreement scheme (hereafter referred to as fwAKA) for IoD applications based on elliptic curve cryptography, physical unclonable function, hash function, and XOR operation. The fwAKA only requires two handshakes to achieve authenticated key agreement. We prove that the fwAKA is perfectly secure in the adversarial setting through the security verification using the AVISPA. We set up a simulation environment, implement the fwAKA and its counterparts, and conduct performance evaluation in terms of communication overhead and running time. Experimental results indicate that not only is the fwAKA robust against well-known attacks but also it is more resource-efficient than its opponents.
Cong Pu
PIMRC1
2023 Deep Learning Assisted Channel Estimation for Cell-Free Distributed MIMO Networks
abstract
Pilot contamination poses a critical challenge for channel estimation in dense cell-free (CF) distributed multiple-input multiple-output (CF-DMIMO) wireless networks. State-of-the-art channel estimation schemes require inversion of a high-dimensional channel covariance matrix, which is practically infeasible for dense CF-DMIMO networks owing to the requirement of large storage and high dimensional computational complexity. In this work, we investigate channel estimation problem for a CF-DMIMO network, where both terrestrial and aerial users are jointly supported by distributed access points. We formulate the problem of estimating channel coefficients from the received in-phase/quadrature (I/Q) samples as a non-linear regression problem and propose two deep-learning aided channel estimation schemes for the considered network, namely, deep model-agnostic neural network (DMANN) and deep successive contamination cancellation (DSCC) schemes. Compared to the state-of-the-art channel estimation schemes for CF-DMIMO networks, the proposed schemes (i) tackle the unavoidable pilot contamination issue in dense CF-DMIMO networks while estimating the channel gains for both terrestrial and aerial users; (2) does not require prior knowledge of signal-to-noise ratios; and (3) works well in the presence of non-Gaussian correlated noise. Simulation results demonstrate the effectiveness of the proposed schemes over state-of-the-art channel estimation schemes in various use cases of the CF-DMIMO networks.
Imtiaz Ahmed 0001, Md. Zoheb Hassan, Ahmed Rubaai, Kamrul Hasan 0008, Cong Pu, Jeffrey H. Reed
WiMob5
2022 SecureIoD: A Secure Data Collection and Storage Mechanism for Internet of Drones
abstract
Thanks to rapid advancements in microprocessors, battery technologies, and lightweight materials, unmanned aerial vehicles (UAVs), commonly known as drones, have received signif-icant interest in the past few years. As drone-related commercial and civilian applications are flourishing, Internet-of-Drones (IoD) is moving into the fast lane and quickly becoming a highly anticipated network paradigm, where drones and Zone Service Providers (ZSPs) coordinate knowledge sharing in a reliable, accurate, and efficient way. However, for the sake of both strategic and financial value to business and mission critical applications, it is of vital importance to address both data security and privacy preservation issues brought by drones' inherent resource constraints and wide-open wireless medium. In this paper, we propose a secure data collection and storage mechanism, also called SecureIoD, for the IoD environment. In SecureIoD, drones and ZSPs first mutually authenticate each other and establish a secure session key before sharing any sensitive data via an insecure wireless channel. Then, ZSPs pack the collected data into blocks and compete to add their blocks into the blockchain. We also propose a joint Proof-of- Work (PoW) and Proof-of-Stake (PoS) consensus mechanism to select the miner ZSP, where the more transactions are in the block, the easier a ZSP can solve the cryptographic puzzle. We present security verification and analysis to show that SecureIoD can resist various security attacks. Finally, we develop a real-world testbed, implement SecureIoD and existing SDDM and BACSIoD schemes, and carry out extensive simulation experiments for performance evaluation and analysis. Experimental results reveal that not only does SecureIoD have lower computation cost, energy consumption, miner selection time, and communication overhead, but also offer better security features and capabilities.
Cong Pu, Andrew Wall, Imtiaz Ahmed 0001, Kim-Kwang Raymond Choo
MDM1
2022 Mitigating Routing Misbehavior in the Internet of Drones Environment
abstract
Despite initially made for military purposes, drones have presented themselves to consumers, and the drone industry is expected to witness a significant growth during the forecast period. As the number of drones in the sky keeps growing, a fleet of drones and stationary zone service providers (ZSPs) can form an airborne network which is termed the Internet of Drones (IoD). In order to achieve the objectives of efficient information sharing and superior team performance, routing protocol plays a vital role for reliable communication in the IoD. However, malicious drones may strategically drop any received packets, and traditional mitigation techniques designed specially for mobile/vehicular ad hoc networks are unable to be directly applied in the IoD as a consequence of the intermittent connectivity between drones. In this paper, we propose a distributed countermeasure, also called CounterRomir, to detect and mitigate routing misbehavior in the IoD. In CounterRomir, a drone keeps the previous signed communication invoice and shares it with the next-hop drone so that the next-hop drone can detect whether the drone has dropped any packets or not. In consideration of a malicious drone likely misstating its communication invoice to avoid detection, each drone saves and sends a small number of past communication invoices to the ZSP which can detect the misstating drone. We develop a comprehensive simulation framework and conduct extensive simulation experiments using OMNeT++ for performance evaluation and analysis. After comparing with prior schemes, we come to the conclusion that CounterRomircan provide admirable performance in terms of detection rate, packet delivery ratio, miss/error detection rate, and the number of dropped packets, indicating an applicable approach against routing misbehavior in the IoD.
Cong Pu, Pingping Zhu
VTC Spring1
2022 Lightweight Sybil Attack Detection in IoT based on Bloom Filter and Physical Unclonable Function
Cong Pu, Kim-Kwang Raymond Choo
Comput. Secur.1
2022 A Lightweight and Privacy-Preserving Mutual Authentication and Key Agreement Protocol for Internet of Drones Environment
abstract
With accelerated advances in various technologies, drones, better known as unmanned aerial vehicles (UAVs), are increasingly commonplace and consequently have a more pronounced impact on society. For example, Internet of Drones (IoD), a new communication paradigm offering fundamental navigation assistance and access to information, has widespread applications ranging from agricultural drones in farming to surveillance drones in the COVID-19 pandemic. The increasingly prominent role of IoD in our society also reinforces the importance of securing such systems against various data privacy and security threats. Operationally, it can be challenging to adopt conventional off-the-shelf security products in an IoD system due to the underpinning characteristics of drones (e.g., dynamic and open communication channel). Therefore in this article, we propose a lightweight and privacy-preserving mutual authentication and key agreement protocol, hereafter referred to as PMAP. The latter uses a physical unclonable function (PUF) and chaotic system to support mutual authentication and establish a secure session key between communication entities in the IoD system. To be specific, PMAP consists of two schemes, namely: 1)${\mathrm{ PMAP}}^{D2Z}$(that mutually authenticates drone and zone service provider (ZSP) and establishes secure session keys) and 2)${\mathrm{ PMAP}}^{D2D}$(that mutually authenticates drones and establishes secure session keys). In addition, PMAP supports conditional privacy preserving so that the genuine identity of drones can only be revealed by trusted ZSPs. We evaluate the security of PMAP using automated validation of Internet security protocols and application (AVISPA), as well as provide formal and informal security analysis to show the resilience of PMAP against various security attacks. We also evaluate the performance of PMAP through extensive experiments and compare its performance with existing AKA and IBE-Lite schemes, whose findings show that PMAP achieves better performance in terms of computation cost, energy consumption, and communication overhead.
Cong Pu, Andrew Wall, Kim-Kwang Raymond Choo, Imtiaz Ahmed 0001, Sunho Lim
IEEE Internet Things J.1
2022 A Lightweight and Anonymous Authentication and Key Agreement Protocol for Wireless Body Area Networks
abstract
As a major building block of Healthcare 4.0, wireless body area networks (WBANs) play an important role in collecting patient’s real-time physical phenomena through small wearable or implantable intelligent medical devices and communicating with remote medical experts using short-range wireless communication techniques. However, the challenges of securing information access are partly evidenced by the difficulty in designing secure and efficient security protocols. For example, existing authentication and key agreement schemes have either potential security vulnerabilities or high communication and computation overhead. In this article, we propose a lightweight and anonymous authentication and key agreement protocol, also called liteAuth, for WBANs. In our approach, mutual authentication and session key agreement are achieved using the Tinkerbell map-based random shuffling, physical unclonable function, one-way hash function, and bitwise exclusive OR operation. The security of liteAuth is first verified using the AVISPA tool, and then its cyber resilience is analyzed. In addition, we develop a real-world testbed, implement liteAuth and two existing schemes (i.e., PSLAP and HARCI), and conduct experiments for performance evaluation and analysis. Experimental results indicate that liteAuth can improve the performance of communication overhead and computation time as well as reduce energy consumption, while meeting all security requirements.
Cong Pu, Haleigh Zerkle, Andrew Wall, Sunho Lim, Kim-Kwang Raymond Choo, Imtiaz Ahmed 0001
IEEE Internet Things J.1
2021 Defending against Flooding Attacks in the Internet of Drones Environment
abstract
Even though drones are still in the infancy period in terms of widespread adoption and use, they have already pierced through solid conventional barriers in various domains of industry. As the usage of drones is becoming commonplace, a next generation aerial communication paradigm, Internet of Drones (IoD), has been proposed to further explore drone technology in a broad scope. IoD relies on the mobility of drones and intermittent drone-to-drone (D2D) and drone-to-ground station (D2I) communications for information sharing and exchange. Because of high mobility and resource constraints, IoD is defenseless to flooding attacks where an adversary sends an excessive amount of packets (original or replica) to legitimate drones with the intention of draining the limited IoD resources (i.e., communication bandwidth and drones' storage space). In this paper, we propose a lightweight distributed detection scheme, hereafter referred to as Lids, to defend against flooding attacks in the IoD environment. The basic idea of Lids is that each drone counts the number of packets that it has sent within a predefined time interval and shares the self-counting report with other drones during contacts. The receiving drones store the self-counting reports while flying and send them to nearby ground station which will check the consistency of self-counting reports to detect flooding attacks. For performance evaluation, we implement Lids and its counterparts (i.e., DAFA and LFADefender) in OMNeT++ network simulator and conduct extensive experiments in terms of detection ratio, miss detection ratio, detection latency, as well as energy consumption. Our experimental results indicate the superior performance of Lids to defend against flooding attacks in the IoD environment.
Cong Pu, Pingping Zhu
GLOBECOM1
2020 A Theil Index-Based Countermeasure Against Advanced Vampire Attack in Internet of Things
abstract
In the last decade, design, development, and advancement in embedded processing, sensing, and wireless communication have fueled the emergence of Internet of Things (IoT), where various smart devices communicate and cooperate with each other and existing communication systems to achieve the goal of sharing information and coordinating decisions. Meanwhile, IPv6-based Low Power and Lossy Network (LLN), which is a major building block of IoT, has attracted a fair amount of attention for all sorts of IoT applications and deployments. In order to provide IPv6 connectivity to an enormous number of resource-constrained smart devices in IoT environment, an efficient routing protocol for IPv6-based LLNs, also widely known as RPL, has been standardized. However, RPL lacks security protection and is vulnerable to various Denial-of-Service (DoS) attacks. In this paper, we first present an advanced vampire attack, which is a novel routing layer specific service disruption and resource exhaustion attack, against RPL in IPv6-based LLNs. Then we propose a Theil index-based countermeasure to effectively detect and mitigate advanced vampire attack. The basic idea of the proposed Theil index-based countermeasure is that each node measures the distribution of destination MAC addresses in the received data packets to detect advanced vampire attack. Through experimental study, the effectiveness of the Theil index-based countermeasure is validated, indicating a viable approach against advanced vampire attack in the IoT.
Cong Pu, Jacqueline Brown, Logan Carpenter
HPSR1
2020 Lightweight Authentication Protocol for Unmanned Aerial Vehicles Using Physical Unclonable Function and Chaotic System
abstract
With the continuous miniaturization of electronic devices and the recent advancement in wireless communications, unmanned aerial vehicles (UAVs) will find many new uses in people’s production and life, bringing great convenience to the public. Meanwhile, the cybersecurity of UAVs is gaining significant attention due to both financial and strategic information and value involved in aerial applications, and UAV and sensitive data collected by embedded sensors are subject to new security challenges and privacy issues. Traditional cryptographic techniques can be deployed to provide fundamental security services, however, they have been shown to be inefficient because of intrinsic resource constraints of UAVs and the open nature of wireless communication. For the sake of providing secure authentication between communication parties and further ensuring data security and privacy, this paper proposes a lightweight mutual authentication protocol, also referred to as PCAP, for secure communications between UAVs and ground station. The basic idea of the PCAP is that UAV and ground station use the challenge-response pair of physical unclonable function as the initial condition of chaotic system to randomly shuffle the message which piggybacks a seed to generate a secret session key. We conduct simulation experiments using OMNeT++to validate the effectiveness of the PCAP. The simulation results show that the PCAP can achieve better performance in terms of computation cost, communication overhead, and energy consumption of communication compared to prior cryptographic technique, indicating a viable approach for securing communications between UAVs and ground station.
Cong Pu
LANMAN1
2020 Sybil Attack in RPL-Based Internet of Things: Analysis and Defenses
abstract
Over the past few years, Internet of Things (IoT) has emerged as a promising paradigm that connects various physical devices to the Internet, and contributes to the development of countless next-generation applications. As a major enabler for IoT, IPv6-based low-power and lossy networks (LLNs) have been receiving considerable attention as a mature solution for scalable data collection in a ubiquitous computing and communication infrastructure. In order to provide efficient point-to-multipoint and multipoint-to-point communication, a novel routing protocol for LLNs, also well known as RPL, has been proposed and standardized. Nonetheless, due to devices' constraints on processing power, memory, and energy, and the lack of specific security models of the RPL routing protocol, LLNs become an ideal target for various security attacks. In this article, we propose a Gini index-based countermeasure, also called GINI, to effectively detect and mitigate sybil attack in RPL-based LLNs, where the malicious node multicasts an excessive number of DODAG information solicitation (DIS) messages with different fictitious identities to cause the legitimate nodes to restart the Trickle algorithm frequently and broadcast a large number of DODAG information object (DIO) messages to quickly drain the limited energy resource of legitimate nodes. We also present a simple analytical model and its numerical results in terms of detection rate. We evaluate the proposed GINI countermeasure through extensive simulation experiments using OMNeT++ and compare its performance with two existing schemes, SecRPL and two-step detection. The simulation results show that the proposed GINI countermeasure can not only improve the detection rate and detection latency but also reduce energy consumption, indicating a viable approach against sybil attack in the IoT. For continuous improvement and future research, we further discuss the proposed GINI countermeasure in terms of design features, design constraints, and possible extensions.
Cong Pu
IEEE Internet Things J.1
2019 Energy Depletion Attack Against Routing Protocol in the Internet of Things
abstract
Low power and lossy networks (LLNs) are undeniably vulnerable to various Denial-of-Service (DoS) attacks due to the shared wireless medium, the lack of physical protection, and instinctive resource constraints. In this paper, we propose a misbehavior-aware threshold detection scheme, called MAD, against energy depletion attack in RPL-based LLNs, where a malicious node intentionally generates and sends a large number of packets to legitimate nodes to excessively consume the energy resource of intermediate nodes located along the forwarding paths, and finally makes the resource-constrained network suffer from denial of service. In the MAD, each node maintains a count of the number of received packets from its child node within a specific time window, and then compares the count with a dynamically calculated threshold to detect potential malicious node. We conduct extensive simulation experiments for performance evaluation and comparison with the original RPL with and without adversary, respectively. The simulation results show that the proposed scheme is a viable approach against energy depletion attack in RPL-based LLNs.
Cong Pu
CCNC1
2019 Digital Signature Based Countermeasure Against Puppet Attack in the Internet of Things
abstract
In order to achieve the goal of smooth interaction and communication, a novel distance vector and source routing protocol, also officially referred to as RPL, has been proposed for IPv6-based Low Power and Lossy Networks (LLNs) which serve as a major component in the architecture of Internet of Things (IoT). Unfortunately, IoT devices are often equipped with limited energy and extremely constrained with regard to the capabilities of computing and communicating, thus, IoT and its applications are seriously vulnerable to diverse cyber attacks, and investigating possible attacks against IoT-related routing protocol is a top priority to enhance the security of IoT systems in the future. In this paper, we propose a digital signature based countermeasure along with other techniques to defend against puppet attack in LLNs running with RPL. The experimental results indicate that the proposed digital signature based countermeasure can not only reduce the performance impact of puppet attack significantly, but also can accurately detect and effectively mitigate puppet attack.
Cong Pu, Logan Carpenter
NCA1
2019 To Route or To Ferry: A Hybrid Packet Forwarding Algorithm in Flying Ad Hoc Networks
abstract
The capabilities and roles of unmanned aerial vehicles, a.k.a. drones, have been rapidly evolving as a result of the advances in processing, sensing, communicating, and networking technologies of robotic systems. Because of the versatility, flexibility, easy installation, and relatively small operating expenses of drones, Flying Ad Hoc Networks (FANETs) consisting of a fleet of drones endowed with sensing, computing, and wireless communicating capabilities are promptly proliferating and representing a key enabler for Internet-of-Drones and its applications. Unfortunately, reliable packet forwarding in FANETs is not always guaranteed because of unstable link quality and intermittent connectivity caused by high mobility of drones. In this paper, we propose a hybrid packet forwarding algorithm, named HYBDfwd, to efficiently and reliably deliver data packets to ground destination in FANETs. The HYBDfwdconsists of two schemes: end-to-end routing and delay-tolerant forwarding. In end-to-end routing, the drone initiates a route discovery procedure to find an end-to-end routing path to deliver data packets to ground destination. In case no end-to-end routing path exists, delay-tolerant forwarding is applied, where the drone forwards data packets to the ferry drone that is moving to ground destination or it carries data packets and moves to ground destination to deliver data packets. We evaluate the proposed hybrid packet forwarding algorithm through extensive simulation experiments using OMNeT++ and compare its performance with a prior motion-driven packet forwarding algorithm, and experimental results indicate that the proposed hybrid packet forwarding algorithm can be a viable approach in FANETs.
Cong Pu, Logan Carpenter
NCA1
2019 Active detection in mitigating routing misbehavior for MANETs
Cong Pu, Sunho Lim, Jinseok Chae, Byungkwan Jung
Wirel. Networks1
2018 Mitigating Forwarding misbehaviors in RPL-based low power and lossy networks
abstract
Low power and lossy networks (LLNs) are rapidly emerging as an important part of ubiquitous computing, and serving as a major building block for the communication infrastructure in the presence of Internet-of-Things (IoT). Routing protocol for low power and lossy networks (RPL) is a novel routing protocol standardized to enable the integration of resources-constrained devices into the Internet. However, due to the shared radio medium, the lack of physical protection and security requirements of inherent routing protocol, low power and lossy networks are admittedly threatened by diverse Denial-of-Service (DoS) attacks that primarily disrupt network protocols and interfere with on-going communications. In this paper, we propose a monitor-based approach, called CMD, to mitigate forwarding misbehaviors in LLNs running with RPL, where single or multiple malicious nodes randomly or strategically drop any incoming Data packet. The basic idea of the CMD is that each node monitors the forwarding behaviors of the preferred parent node to observe the packet loss rate, compares the observation result with the collected packet loss rate from one-hop neighbor nodes, and detects the forwarding misbehaviors of the preferred parent node. We evaluate the proposed scheme through extensive simulation experiments using OMNeT++ and compare its performance with the original RPL protocol and the existing two-step detection scheme. The simulation results show that the proposed scheme can not only improve the detection rate and packet delivery ratio (PDR) but also can reduce the energy consumption and isolation latency.
Cong Pu, Salam Hajjar
CCNC1
2018 Mitigating Suppression Attack in Multicast Protocol for Low Power and Lossy Networks
abstract
The following topics are dealt with: telecommunication traffic; telecommunication network routing; Internet; protocols; wireless sensor networks; transport protocols; Internet of Things; computer network security; resource allocation; learning (artificial intelligence).
Cong Pu, Xitong Zhou, Sunho Lim
LCN1
2018 A Novel Energy Harvesting Aware IEEE 802.11 Power Saving Mechanism
Yigitcan Celik, Cong Pu
WASA2
2018 VRSense: Validity region sensitive query processing strategies for static and mobile point-of-interests in MANETs
Byungkwan Jung, Sunho Lim, Jinseok Chae, Cong Pu
Comput. Commun.4
2018 EYES: Mitigating forwarding misbehavior in energy harvesting motivated networks
Cong Pu, Sunho Lim, Byungkwan Jung, Jinseok Chae
Comput. Commun.1